2.5
CVE-2026-20757
- EPSS 0.07%
- Veröffentlicht 03.03.2026 03:15:54
- Zuletzt bearbeitet 18.08.2026 15:54:36
- CVE-Watchlists
- Unerledigt
Improper Locking vulnerability (CWE-667) in Gallagher Morpho integration allows a privileged operator to cause a limited denial-of-service in the Command Centre Server. This issue affects Command Centre Server: 9.40 prior to vEL9.40.1976(MR1), 9.30 prior to vEL9.30.3382 (MR4), 9.20 prior to vEL9.20.3783 (MR6), 9.10 prior to vEL9.10.4647 (MR9), all versions of 9.00 and prior.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gallagher ≫ Command Centre Version < 9.10.4647
Gallagher ≫ Command Centre Version >= 9.20.1043 < 9.20.3783
Gallagher ≫ Command Centre Version >= 9.30.1594 < 9.30.3382
Gallagher ≫ Command Centre Version >= 9.40.1359 < 9.40.1976
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.07% | 0 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosures@gallagher.com | 2.5 | 1 | 1.4 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
|
CWE-667 Improper Locking
The product does not properly acquire or release a lock on a resource, leading to unexpected resource state changes and behaviors.
https://security.gallagher.com/en-NZ/Security-Advisories/CVE-2026-20757